In all three cases the vulnerabilities addressed by the update create a possible means for miscreants to smuggle malware onto, or otherwise attack, vulnerable Windows boxes. But the IE update deserves special attention since hackers are actively exploiting the bug to attack vulnerable machines, the SANS Institute's Internet Storm Centre warns.

The remaining four "important" updates address bugs including a brace of bugs in Windows Vista and a security bug in DRM software from Macrovision that comes bundled with Windows. Macrovision issued a patch to address flaws in its SafeDisk utility in November, which is just as well because the bug has become the target of various attacks by crackers.

Microsoft's December patch summary can be found here. A rather more colourful (graphical) overview from SANS can be found here. ®